If you received a data breach notification letter referencing DentaQuest, LLC, you are among the millions of patients caught in one of the most severe healthcare cybersecurity attacks of 2026. As one of the largest administrators of Medicaid, CHIP, Medicare Advantage, and commercial dental plans in the United States, DentaQuest coordinates oral and vision care for more than 35 million Americans.
Because DentaQuest operates behind your primary health insurer, many recipients do not recognize the corporate name on the envelope. This comprehensive report outlines how the intrusion occurred, what data was exposed, and the immediate security measures you must take to shield your financial identity.
1. Incident Autopsy: The ShinyHunters Cyberattack
According to official breach disclosures filed with state regulatory bodies (including the Massachusetts, Texas, and South Carolina Attorneys General offices), the breach followed a systematic corporate extortion pattern:
- Network Infiltration: Threat actors penetrated a limited segment of DentaQuest’s internal network on May 17, 2026, exfiltrating healthcare enrollment databases and ASC X12 electronic data interchange (EDI) transaction batches before the network was locked down on May 20, 2026.
- The Extortion Campaign: The threat group ShinyHunters added DentaQuest to their dark-web leak portal following a rejected “pay-or-leak” ransom demand, distributing approximately 234 gigabytes of unencrypted member files and internal archives.
- Aggregated Record Leak: Independent breach aggregation services verified that the leaked datasets contained more than 2.6 million unique email records paired with complete identity profiles, government registration IDs, and treatment records.
| Key Incident Metric | Confirmed Details | Threat Level to Victims |
|---|---|---|
| Attack Window | May 17, 2026 – May 20, 2026 | Contained by IT security |
| Total Confirmed Impact | 15,000,000+ Verified Patient Records | High (Nationwide Scope) |
| Threat Actor Responsible | ShinyHunters Extortion Group | High (Public Data Leak) |
| Remediation Provided | 24 Months Free Kroll Identity Monitoring | Active Enrollment Available |
2. What Specific Information Was Compromised?
Unlike credential-stuffing incidents that only compromise passwords, this breach exposed a dangerous intersection of Personally Identifiable Information (PII) and Protected Health Information (PHI):
- Core Identity Anchors: First and last name, date of birth, home address, contact phone number, and personal email.
- Federal & State Identifiers: Social Security numbers (SSNs), Medicare IDs, Medicaid member identification numbers, and government-issued driver’s licenses.
- Clinical & Insurance Records: Dental and vision provider names, procedure codes, diagnosis details, insurance policy group numbers, and claim payment breakdowns.
3. How to Activate Your Free Kroll Credit Monitoring
DentaQuest is offering all impacted members 24 months of comprehensive identity monitoring, single-bureau credit tracking, fraud consultation, and identity theft restoration services managed by Kroll at zero out-of-pocket cost.
- Locate Your Notice Letter: Find the physical letter delivered to your mailbox. You will need the printed Activation Code and Verification ID.
- Redeem Online: Visit the official portal at
enroll.krollmonitoring.com/redeemto begin registration. - Mind the 90-Day Deadline: You must complete enrollment within 90 days of the date stamped on your breach notice. Once that window closes, unclaimed activation codes expire.
- Phone Enrollment Support: If you misplaced your letter or need activation assistance, contact Kroll’s dedicated DentaQuest support line at 1-844-959-7163 (available Monday through Friday).
4. Essential Defensive Actions You Must Take Now
Because leaked health and insurance records cannot be revoked or changed like a simple password, you must establish external financial guardrails:
- Place a Free Credit Freeze: Contact all three credit bureaus—Experian, Equifax, and TransUnion—to lock your credit file. A credit freeze blocks identity thieves from opening credit cards, auto loans, or mortgages in your name, even if they possess your full SSN and birthdate.
- Establish an Initial Fraud Alert: If you do not freeze your file, place a free 1-year initial fraud alert on your credit report. This legally mandates that creditors verify your identity over the phone before opening new lines.
- Audit Your Healthcare Explanation of Benefits (EOB): Closely inspect all physical and digital statements from your dental and health insurer. If you notice procedures, extractions, or cleanings you never received, report medical identity theft directly to your insurance company immediately.
- Watch for Targeted Spear-Phishing: Scammers exploit leaked records by posing as DentaQuest or your insurance company via text, email, or phone. Never share account passwords or confirm two-factor authorization codes with unsolicited callers.
Even if your primary dental benefits have since transitioned to another provider, your archival records may still have been stored within DentaQuest’s historical systems. If you used state Medicaid or employer-sponsored dental coverage anytime over the past decade, monitor your credit reports and enroll in the complimentary Kroll coverage as soon as your notification arrives.